官术网_书友最值得收藏!

Keystone - identity management

From an architectural perspective, Keystone presents the simplest service in the OpenStack composition. It is the core component and provides an identity service comprising authentication and authorization of tenants in OpenStack. Communications between different OpenStack services are authorized by Keystone to ensure that the right user or service is able to utilize the requested OpenStack service. Keystone integrates with numerous authentication mechanisms such as username/password and token/authentication-based systems. Additionally, it is possible to integrate it with an existing backend such as the Lightweight Directory Access Protocol (LDAP) and the Pluggable Authentication Module (PAM).

Keystone also provides a service catalog as a registry of all the OpenStack services.

With the evolution of Keystone, many features have been implemented within recent OpenStack releases leveraging a centralized and federated identity solution. This will allow users to use their credentials in an existing, centralized, sign-on backend and decouples the authentication mechanism from Keystone.

The federation identity solution becomes more stable within the OpenStack Juno release, which engages Keystone as a Service Provider (SP), and uses and consumes from a trusted Provider of Identity (IdP), user identity information in SAML assertions, or OpenID Connect claims. An IdP can be backed by LDAP, Active Directory, or SQL.

主站蜘蛛池模板: 平乐县| 彭州市| 正安县| 宝山区| 尖扎县| 渑池县| 洛川县| 海晏县| 肇源县| 乐至县| 建水县| 康定县| 合川市| 柞水县| 阿拉尔市| 皮山县| 游戏| 千阳县| 南京市| 彰武县| 仙游县| 彰武县| 革吉县| 汶川县| 封开县| 随州市| 阳城县| 花莲县| 乐至县| 嘉善县| 横山县| 锡林郭勒盟| 墨玉县| 岳池县| 徐汇区| 靖远县| 黄山市| 沅陵县| 岐山县| 页游| 宁海县|